Vendor
A vulnerability in the External Secrets Operator enables authenticated users to bypass label enforcement checks in webhook generators, allowing unauthorized exfiltration of Kubernetes secrets to malicious URLs.